diff mbox series

[scarthgap] gstreamer1.0-plugins-bad: Security fix for CVE-2026-3082

Message ID 20261001063353.102615-1-rsangam@mvista.com
State New
Delegated to: Yoann Congal
Headers show
Series [scarthgap] gstreamer1.0-plugins-bad: Security fix for CVE-2026-3082 | expand

Commit Message

Rohini Sangam Oct. 1, 2026, 6:33 a.m. UTC
Pick patch from [1] also mentioned at Debian tracker in [2]

[1] https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354
[2] https://security-tracker.debian.org/tracker/CVE-2026-3082

Signed-off-by: Rohini Sangam <rsangam@mvista.com>
---
 .../CVE-2026-3082.patch                       | 46 +++++++++++++++++++
 .../gstreamer1.0-plugins-bad_1.22.12.bb       |  1 +
 2 files changed, 47 insertions(+)
 create mode 100644 meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
diff mbox series

Patch

diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
new file mode 100644
index 0000000000..26e27ee5f5
--- /dev/null
+++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad/CVE-2026-3082.patch
@@ -0,0 +1,46 @@ 
+From 83e9225bb9e89948e7b1c9f37ef9218d2dcde354 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?V=C3=ADctor=20Manuel=20J=C3=A1quez=20Leal?=
+ <vjaquez@igalia.com>
+Date: Wed, 11 Feb 2026 22:07:49 +0100
+Subject: [PATCH] libs: jpegparser: boundary checks before copying it
+
+READ_BYTES macro reads data from a byte reader and then copy it to a storage
+variable. This patch adds a validation that the length to read cannot be bigger
+than the storage size.
+
+This macro right now is used only for storage variables of guint8 arrays.
+
+We have validated in the specification (sections F.1.2.1.2 and F.1.2.2.1 in ITU
+T.81) that Huffman tables (both AC and DC) aren't bigger than 256.
+
+Fixes SA-2026-0003, CVE-2026-3082, ZDI-CAN-28840.
+
+Fixes: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/4899>
+Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/10946>
+
+CVE: CVE-2026-3082
+Upstream-Status: Backport [https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/83e9225bb9e89948e7b1c9f37ef9218d2dcde354]
+
+Signed-off-by: Rohini Sangam <rsangam@mvista.com>
+---
+ gst-libs/gst/codecparsers/gstjpegparser.c | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/gst-libs/gst/codecparsers/gstjpegparser.c b/gst-libs/gst/codecparsers/gstjpegparser.c
+index 6411076..86125b3 100644
+--- a/gst-libs/gst/codecparsers/gstjpegparser.c
++++ b/gst-libs/gst/codecparsers/gstjpegparser.c
+@@ -79,6 +79,10 @@ ensure_debug_category (void)
+ 
+ #define READ_BYTES(reader, buf, length) G_STMT_START {          \
+     const guint8 *vals;                                         \
++    if (length > sizeof (buf)) {                                \
++      GST_WARNING ("data size is bigger than its storage");     \
++      goto failed;                                              \
++    }                                                           \
+     if (!gst_byte_reader_get_data (reader, length, &vals)) {    \
+       GST_WARNING ("failed to read bytes, size:%d", length);    \
+       goto failed;                                              \
+-- 
+2.44.4
+
diff --git a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
index f6d0711bd8..64e0aa6dcb 100644
--- a/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
+++ b/meta/recipes-multimedia/gstreamer/gstreamer1.0-plugins-bad_1.22.12.bb
@@ -12,6 +12,7 @@  SRC_URI = "https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad
            file://0005-v4l2codecs-Always-chain-up-to-parent-decide_allocati.patch \
            file://CVE-2025-3887-1.patch \
            file://CVE-2025-3887-2.patch \
+           file://CVE-2026-3082.patch \
            "
 SRC_URI[sha256sum] = "388b4c4412f42e36a38b17cc34119bc11879bd4d9fbd4ff6d03b2c7fc6b4d494"